logo

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

ID: 93e48d46-d481-5ab2-ab1a-21f8d4d440c9

STIX ID: report--93e48d46-d481-5ab2-ab1a-21f8d4d440c9

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Pierluigi Paganini

...
...

Microsoft tracked a macOS information stealer called MacSync Stealer not by blocking domains but by correlating persistent behavioral patterns: terminal-based social engineering (ClickFix), curl downloads from /curl/[token], AppleScript-driven execution, staging/compression of stolen data under /tmp/sync*, and chunked HTTP PUT uploads with upload_id/chunk_index/total_chunks. The behavior-led approach linked over 30 domains, revealed static API-key reuse across some C2s, and emphasizes building detections around the attack sequence rather than ephemeral domain lists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.